In a multiplex dashboard (one process serving every profile on the host),
a secondary profile's terminal.backend could leak into the shared
os.environ and silently override the launch profile's terminal backend.
A profile configured for terminal.backend: ssh would find itself running
every command locally because a sibling profile with backend: local had
polluted the shared environment.
The tell is an asymmetric env state on the launch session:
TERMINAL_ENV=local # leaked from a sibling profile
TERMINAL_SSH_HOST=10.10.0.103 # still the launch profile's, untouched
A restart does not help: as soon as the sibling profile is touched again
(a turn, a cron tick), the shared env is re-poisoned.
Root cause: env_loader._reapply_terminal_config_bridge() guards "only
re-bridge config into the shared os.environ when this load is for the
process's own profile" via _process_hermes_home(). That helper delegated
to get_hermes_home(), which follows the context-local
set_hermes_home_override a per-request task installs. When a per-turn
handler is scoped to a secondary profile and triggers a dotenv reload,
both sides of the comparison resolve to that secondary profile, the guard
passes, and the bridge writes the wrong profile's terminal.backend into
the shared environment. Because the secondary profile's config carries no
TERMINAL_SSH_* keys, only TERMINAL_ENV is overwritten, producing the
asymmetric state above.
The helper was introduced for the config-cache key (where following the
active home is correct) and later reused for the terminal bridge guard,
where the override-following semantics are wrong.
Fix: delegate _process_hermes_home() to get_process_hermes_home(), the
override-immune resolver built for exactly this. It reflects the scope the
process was launched under, ignoring per-task overrides. Both call sites
(the bridge guard and the secrets-cache reuse check) want the true process
home. Single-profile / CLI behaviour is unchanged: with no active
override the two resolvers are identical.
Complements the terminal_tool._active_environments session-key fix: that
scopes the per-session environment cache; this keeps the shared os.environ
the cache reads TERMINAL_ENV from uncontaminated in the first place.
Adds tests/hermes_cli/test_terminal_bridge_profile_scope.py covering both
the override-immune resolver and the no-leak reload behaviour.
94 lines
3.4 KiB
Python
94 lines
3.4 KiB
Python
"""Regression: the terminal config→env re-bridge is scoped to the *true*
|
|
process profile, never a per-task ``set_hermes_home_override``.
|
|
|
|
The multiplex dashboard serves every profile on the host from one process,
|
|
so ``os.environ`` is shared across all of them. A per-turn handler scoped to
|
|
a secondary profile (via ``set_hermes_home_override``) must NOT cause that
|
|
profile's ``terminal.backend`` to be bridged into the shared environment —
|
|
otherwise a ``local`` sibling profile silently clobbers the launch profile's
|
|
``TERMINAL_ENV=ssh`` (leaving its ``TERMINAL_SSH_*`` intact), and the launch
|
|
session runs every command locally instead of over SSH.
|
|
|
|
The guard in ``env_loader._reapply_terminal_config_bridge`` compares the
|
|
loaded home against the process home. It must use the override-immune
|
|
``get_process_hermes_home()`` so the comparison reflects the launch scope,
|
|
not whichever profile the current task is scoped to.
|
|
"""
|
|
|
|
import os
|
|
|
|
import pytest
|
|
|
|
import hermes_cli.env_loader as env_loader
|
|
from hermes_constants import (
|
|
set_hermes_home_override,
|
|
reset_hermes_home_override,
|
|
)
|
|
|
|
|
|
def _write_terminal_config(home, text: str) -> None:
|
|
home.mkdir(parents=True, exist_ok=True)
|
|
(home / "config.yaml").write_text(text)
|
|
|
|
|
|
@pytest.fixture(autouse=True)
|
|
def _clean_terminal_env(monkeypatch):
|
|
for name in ("TERMINAL_ENV", "TERMINAL_SSH_HOST", "TERMINAL_SSH_USER"):
|
|
monkeypatch.delenv(name, raising=False)
|
|
yield
|
|
|
|
|
|
def test_process_hermes_home_ignores_task_override(tmp_path, monkeypatch):
|
|
"""The guard's home resolver must not follow a per-task override."""
|
|
launch_home = tmp_path / "laptop"
|
|
other_home = tmp_path / "tommy"
|
|
launch_home.mkdir()
|
|
other_home.mkdir()
|
|
monkeypatch.setenv("HERMES_HOME", str(launch_home))
|
|
|
|
token = set_hermes_home_override(str(other_home))
|
|
try:
|
|
assert (
|
|
env_loader._process_hermes_home().resolve() == launch_home.resolve()
|
|
), "process home leaked to the per-task override profile"
|
|
finally:
|
|
reset_hermes_home_override(token)
|
|
|
|
|
|
def test_secondary_profile_reload_does_not_bridge_into_shared_env(
|
|
tmp_path, monkeypatch
|
|
):
|
|
"""A secondary profile's terminal.backend must not touch os.environ.
|
|
|
|
Simulates the dashboard multiplex: process launched under ``laptop``
|
|
(ssh), a per-turn handler scoped to ``tommy`` (local) triggers a dotenv
|
|
reload for tommy's home. The launch session's TERMINAL_ENV must survive.
|
|
"""
|
|
launch_home = tmp_path / "laptop"
|
|
other_home = tmp_path / "tommy"
|
|
_write_terminal_config(
|
|
launch_home,
|
|
"terminal:\n"
|
|
" backend: ssh\n"
|
|
" ssh_host: 10.10.0.103\n"
|
|
" ssh_user: bergmann\n",
|
|
)
|
|
_write_terminal_config(other_home, "terminal:\n backend: local\n")
|
|
monkeypatch.setenv("HERMES_HOME", str(launch_home))
|
|
|
|
# Launch profile's backend is what the shared env carries.
|
|
monkeypatch.setenv("TERMINAL_ENV", "ssh")
|
|
monkeypatch.setenv("TERMINAL_SSH_HOST", "10.10.0.103")
|
|
|
|
# A per-turn handler for the secondary profile is scoped via the contextvar
|
|
# and drives a reload for tommy's home.
|
|
token = set_hermes_home_override(str(other_home))
|
|
try:
|
|
env_loader._reapply_terminal_config_bridge(other_home)
|
|
finally:
|
|
reset_hermes_home_override(token)
|
|
|
|
# tommy's `local` must NOT have leaked into the shared process env.
|
|
assert os.environ["TERMINAL_ENV"] == "ssh"
|
|
assert os.environ["TERMINAL_SSH_HOST"] == "10.10.0.103"
|